feat: add read-only workspace and secret management UI

This commit is contained in:
2026-08-14 17:38:24 +02:00
parent e902f758b1
commit 3978008aed
8 changed files with 586 additions and 1181 deletions
+122 -170
View File
@@ -1,213 +1,165 @@
import { QueryClient, QueryClientProvider } from "@tanstack/react-query";
import { render, screen, waitFor, within } from "@testing-library/react";
import userEvent from "@testing-library/user-event";
import { QueryClient, QueryClientProvider } from "@tanstack/react-query";
import { http, HttpResponse } from "msw";
import { afterEach, beforeEach, expect, test, vi } from "vitest";
import { beforeEach, expect, test, vi } from "vitest";
import { server } from "../test/msw";
import { workspaceRevisionFixture, workspaceSummaryFixture } from "../test/workspace-fixtures";
import { canonicalWorkspaceFixture, workspaceRevisionFixture, workspaceSummaryFixture } from "../test/workspace-fixtures";
import { WorkspaceManager } from "./WorkspaceManager";
const readyWorkspace = {
workspace: {
schema_version: 3,
id: "psd-clinical",
name: "PSD Clinical",
description: "Clinical data",
language: "en" as const,
},
dwh: {
engine: "postgres" as const,
database: "clinical",
schema: "datawarehouse",
port: 5432,
supported_transports: ["postgres_direct"] as const,
},
semantic_index: {
vector_store: { engine: "qdrant" as const, collection: "clinical", dimensions: 1024 as const, distance: "cosine" as const },
embedding: { provider: "ollama_internal" as const, model: "qwen3-embedding:0.6b" as const, dimensions: 1024 as const },
},
llm_policy: { default: "zai/glm-5.2" as const, allowed: ["zai/glm-5.2"] as const },
evidence: {
source: {
type: "filesystem" as const,
uri: "psd-clinical/evidence",
patterns: ["documents/**/*.pdf"],
max_bytes: 12_000_000,
},
policy: { max_chunk_chars: 8_000, retain_published_generations: 5 },
},
const workspace = canonicalWorkspaceFixture("psd-clinical");
const revision = workspaceRevisionFixture("psd-clinical");
const requirement = {
id: "dwh.password",
connector: "dwh",
label: "Data warehouse password",
description: "Password used by the selected data warehouse connection.",
input: "password",
required: true,
configured: false,
};
const bootstrapWorkspace = {
...readyWorkspace,
workspace: {
...readyWorkspace.workspace,
id: "bootstrap-slot",
name: "Bootstrap slot",
description: "Needs configuration",
},
semantic_index: {
...readyWorkspace.semantic_index,
vector_store: { ...readyWorkspace.semantic_index.vector_store, collection: "bootstrap-slot" },
},
};
function runtimeConfiguration(configured = false) {
return {
workspaceId: "psd-clinical",
revision,
configurationState: configured ? "ready" : "configuration_required",
requirements: [{ ...requirement, configured }],
};
}
function renderManager() {
function renderManager(onClose = vi.fn()) {
const client = new QueryClient({ defaultOptions: { queries: { retry: false } } });
return render(<QueryClientProvider client={client}><WorkspaceManager open onClose={() => undefined} /></QueryClientProvider>);
return {
onClose,
...render(
<QueryClientProvider client={client}>
<WorkspaceManager open onClose={onClose} />
</QueryClientProvider>,
),
};
}
beforeEach(() => {
localStorage.clear();
server.use(
http.get("/api/workspace-registry/status", () =>
HttpResponse.json({ branch: "main", head: "a".repeat(40), ahead: 0, behind: 0, degraded: false })),
http.get("/api/workspace-registry/status", () => HttpResponse.json({
branch: "main",
head: "a".repeat(40),
ahead: 0,
behind: 0,
degraded: false,
repository: {
host: "git.example.test",
repository: "analytics/thoth-workspaces",
transport: "ssh",
},
})),
http.get("/api/workspaces", () => HttpResponse.json([
workspaceSummaryFixture("bootstrap-slot", {
displayName: "Bootstrap slot",
description: "Needs configuration",
configurationState: "configuration_required",
}),
workspaceSummaryFixture("psd-clinical", {
displayName: "PSD Clinical",
description: "Clinical data",
revision: workspaceRevisionFixture("psd-clinical"),
configurationState: "configuration_required",
revision,
}),
])),
http.get("/api/workspaces/psd-clinical", () => HttpResponse.json({
workspace: readyWorkspace,
revision: workspaceRevisionFixture("psd-clinical"),
})),
http.get("/api/workspaces/psd-clinical", () => HttpResponse.json({ workspace, revision })),
http.get("/api/workspaces/psd-clinical/runtime-configuration", () => (
HttpResponse.json(runtimeConfiguration())
)),
);
});
afterEach(() => vi.unstubAllGlobals());
test("uses at least sixty percent of the viewport on desktop", () => {
renderManager();
test("renders catalog slots in order and opens a bootstrap form for configuration_required entries", async () => {
expect(screen.getByRole("dialog")).toHaveClass(
"h-[70vh]",
"w-[94vw]",
"sm:w-[70vw]",
"max-w-[94vw]",
);
});
test("level one explains the read-only Git sequence and the repository update button", async () => {
const user = userEvent.setup();
server.use(http.post("/api/workspace-registry/pull", () => HttpResponse.json({
branch: "main", head: "b".repeat(40), ahead: 0, behind: 0, degraded: false,
})));
renderManager();
expect(await screen.findByRole("heading", { name: "Workspace management" })).toBeVisible();
expect(screen.getByRole("button", { name: "Bootstrap slot" })).toBeVisible();
expect(screen.getByRole("button", { name: "PSD Clinical" })).toBeVisible();
await user.click(screen.getByRole("button", { name: "Bootstrap slot" }));
const overview = screen.getByTestId("workspace-overview");
expect(within(overview).getByText(/Git server such as GitHub, GitLab, or Gitea/i)).toBeVisible();
expect(within(overview).getByText(/configured during ThothII installation/i)).toBeVisible();
expect(within(overview).getAllByText(/managed read-only checkout/i)).toHaveLength(2);
expect(within(overview).getByText(/current active revision remains unchanged/i)).toBeVisible();
expect(within(overview).getByText(/No workspace selection is required/i)).toBeVisible();
expect(await within(overview).findByText("git.example.test/analytics/thoth-workspaces")).toBeVisible();
expect(await screen.findByLabelText("Workspace ID")).toHaveValue("bootstrap-slot");
expect(screen.getByLabelText("Workspace ID")).toBeDisabled();
expect(screen.getByLabelText("Workspace name")).toHaveValue("Bootstrap slot");
expect(screen.getByLabelText("Workspace name")).toBeDisabled();
expect(screen.getByLabelText("Description")).toHaveValue("Needs configuration");
expect(screen.getByRole("button", { name: "Save draft" })).toBeVisible();
expect(screen.getByRole("button", { name: "Create workspace" })).toBeVisible();
await user.click(screen.getByRole("button", { name: "Update workspace repository" }));
expect(await screen.findByText("Workspace repository updated and validated.")).toBeVisible();
expect(screen.queryByText(/import|export|bundle|create a local workspace/i)).not.toBeInTheDocument();
});
test("saves a bootstrap draft locally for a configuration_required slot", async () => {
test("workspace-specific commands remain isolated until a workspace is selected", async () => {
const user = userEvent.setup();
renderManager();
await user.click(await screen.findByRole("button", { name: "Bootstrap slot" }));
await user.clear(screen.getByLabelText("Vector collection"));
await user.type(screen.getByLabelText("Vector collection"), "bootstrap-docs");
await user.click(screen.getByRole("button", { name: "Save draft" }));
await waitFor(() => expect(screen.getByText("Draft saved in this browser.")).toBeVisible());
expect(localStorage.getItem("thothii.workspace-registry.v2.bootstrap.bootstrap-slot")).toContain('"baseCommit"');
expect(localStorage.getItem("thothii.workspace-registry.v2.bootstrap.bootstrap-slot")).not.toContain("baseBlob");
});
test("successful create discards the bootstrap draft and reloads the workspace as read-only", async () => {
const user = userEvent.setup();
let workspacesCalls = 0;
server.use(
http.get("/api/workspaces", () => {
workspacesCalls += 1;
return HttpResponse.json(workspacesCalls === 1 ? [
workspaceSummaryFixture("bootstrap-slot", {
displayName: "Bootstrap slot",
description: "Needs configuration",
configurationState: "configuration_required",
}),
] : [
workspaceSummaryFixture("bootstrap-slot", {
displayName: "Bootstrap slot",
description: "Needs configuration",
revision: workspaceRevisionFixture("bootstrap-slot"),
}),
]);
}),
http.get("/api/workspaces/bootstrap-slot", () => HttpResponse.json({
workspace: bootstrapWorkspace,
revision: workspaceRevisionFixture("bootstrap-slot"),
})),
http.post("/api/workspaces/validate", () => HttpResponse.json({ workspace: bootstrapWorkspace, contract: {} })),
http.post("/api/workspaces/publish", () => HttpResponse.json({ revision: workspaceRevisionFixture("bootstrap-slot") })),
);
localStorage.setItem("thothii.workspace-registry.v2.bootstrap.bootstrap-slot", JSON.stringify({
workspaceId: "bootstrap-slot",
baseCommit: "a".repeat(40),
workspace: bootstrapWorkspace,
updatedAt: "2026-08-04T10:00:00.000Z",
}));
renderManager();
await user.click(await screen.findByRole("button", { name: "Bootstrap slot" }));
await user.click(screen.getByRole("button", { name: "Create workspace" }));
await user.click(screen.getByRole("button", { name: "Validate draft" }));
await user.click(await screen.findByRole("button", { name: "Create workspace" }));
await user.click(screen.getByRole("button", { name: "Confirm create" }));
await waitFor(() => expect(localStorage.getItem("thothii.workspace-registry.v2.bootstrap.bootstrap-slot")).toBeNull());
expect(await screen.findByText(/edit bootstrap-slot\/workspace\.yaml, commit\/push, then Pull/i)).toBeVisible();
expect(screen.queryByRole("button", { name: "Save draft" })).not.toBeInTheDocument();
expect(screen.queryByRole("button", { name: "Create workspace" })).not.toBeInTheDocument();
});
test("ready workspaces stay read-only while keeping pull, export, validate, and installation test actions", async () => {
const user = userEvent.setup();
const createObjectURL = vi.fn(() => "blob:workspace-bundle");
const revokeObjectURL = vi.fn();
class DownloadUrl extends URL {
static createObjectURL = createObjectURL;
static revokeObjectURL = revokeObjectURL;
}
vi.stubGlobal("URL", DownloadUrl);
vi.spyOn(HTMLAnchorElement.prototype, "click").mockImplementation(() => undefined);
server.use(
http.post("/api/workspace-registry/pull", () => HttpResponse.json({ branch: "main", head: "c".repeat(40), ahead: 0, behind: 0, degraded: false })),
http.get("/api/workspaces/psd-clinical/export", () => new HttpResponse(new Blob(["bundle"], { type: "application/zip" }))),
http.post("/api/workspaces/validate", () => HttpResponse.json({ workspace: readyWorkspace, contract: {} })),
http.post("/api/workspaces/psd-clinical/test", () => HttpResponse.json({
activatable: false,
diagnostics: [{ level: "warning", code: "binding_missing", field: "dwh", message: "DWH binding is not configured" }],
})),
);
localStorage.setItem("thothii.workspace-registry.v1.draft.psd-clinical", JSON.stringify({ foo: "bar" }));
renderManager();
expect(screen.queryByRole("heading", { name: "Workspace-specific actions" })).not.toBeInTheDocument();
await user.click(await screen.findByRole("button", { name: "PSD Clinical" }));
expect(await screen.findByText(/edit psd-clinical\/workspace\.yaml, commit\/push, then Pull/i)).toBeVisible();
expect(screen.queryByRole("button", { name: /duplicate workspace|delete workspace|publish draft/i })).not.toBeInTheDocument();
await user.click(screen.getByRole("button", { name: "Pull latest registry" }));
expect(await screen.findByText("Registry updated. Reload a workspace to review its latest revision.")).toBeVisible();
await user.click(screen.getByRole("button", { name: "Export workspace bundle" }));
await waitFor(() => expect(createObjectURL).toHaveBeenCalledTimes(1));
await user.click(screen.getByRole("button", { name: "Validate workspace" }));
expect(await screen.findByText("Workspace definition is valid.")).toBeVisible();
await user.click(screen.getByRole("button", { name: "Test on this installation" }));
expect(await screen.findByText("binding_missing: DWH binding is not configured")).toBeVisible();
expect(within(screen.getByTestId("workspace-diagnostics")).queryByText(/password|token|secret/i)).not.toBeInTheDocument();
expect(await screen.findByRole("heading", { name: "Workspace-specific actions" })).toBeVisible();
expect(screen.getByText(/reads this revision without modifying or publishing it/i)).toBeVisible();
expect(screen.getByText(/checks workspace.yaml and the required workspace directories/i)).toBeVisible();
expect(screen.getByText(/temporary decrypted credentials/i)).toBeVisible();
expect(screen.getByRole("button", { name: "Validate workspace source" })).toBeVisible();
expect(screen.getByRole("button", { name: "Test workspace connections" })).toBeVisible();
});
test("import populates only a matching configuration_required slot and refuses existing workspaces", async () => {
test("secret fields are write-only, clear after blind save, and may be forgotten", async () => {
const user = userEvent.setup();
let savedBody: unknown;
server.use(
http.put("/api/workspaces/psd-clinical/secrets", async ({ request }) => {
savedBody = await request.json();
return HttpResponse.json(runtimeConfiguration(true));
}),
http.delete("/api/workspaces/psd-clinical/secrets/dwh.password", () => (
HttpResponse.json(runtimeConfiguration(false))
)),
);
renderManager();
await user.click(await screen.findByRole("button", { name: "PSD Clinical" }));
server.use(http.post("/api/workspaces/import", () => HttpResponse.json({ draft: { workspace: readyWorkspace, contract: {} } })));
await user.upload(screen.getByLabelText("Import workspace bundle"), new File(["bundle"], "workspace.zip", { type: "application/zip" }));
expect(await screen.findByText(/workspace_invalid: Imported bundle can only bootstrap a matching catalog slot/i)).toBeVisible();
const input = await screen.findByLabelText("Data warehouse password");
expect(input).toHaveValue("");
expect(input).toHaveAttribute("type", "password");
expect(screen.getByText("Not configured")).toBeVisible();
await user.type(input, "one-time-password");
await user.click(screen.getByRole("button", { name: "Save entered secrets" }));
server.use(http.post("/api/workspaces/import", () => HttpResponse.json({ draft: { workspace: bootstrapWorkspace, contract: {} } })));
await user.upload(screen.getByLabelText("Import workspace bundle"), new File(["bundle"], "workspace.zip", { type: "application/zip" }));
expect(await screen.findByText("Imported bootstrap draft saved in this browser. Validate it before creating the descriptor.")).toBeVisible();
expect(localStorage.getItem("thothii.workspace-registry.v2.bootstrap.bootstrap-slot")).not.toBeNull();
await waitFor(() => expect(savedBody).toEqual({
values: { "dwh.password": "one-time-password" },
}));
expect(input).toHaveValue("");
expect(await screen.findByText("Configured")).toBeVisible();
expect(screen.queryByDisplayValue("one-time-password")).not.toBeInTheDocument();
expect(localStorage.length).toBe(0);
await user.click(screen.getByRole("button", { name: "Forget stored Data warehouse password" }));
expect(await screen.findByText("Not configured")).toBeVisible();
});
test("closing clears unsaved secret fields", async () => {
const user = userEvent.setup();
const onClose = vi.fn();
renderManager(onClose);
await user.click(await screen.findByRole("button", { name: "PSD Clinical" }));
await user.type(await screen.findByLabelText("Data warehouse password"), "unsaved-value");
await user.click(screen.getByRole("button", { name: "Close workspace management" }));
expect(onClose).toHaveBeenCalledTimes(1);
expect(screen.queryByDisplayValue("unsaved-value")).not.toBeInTheDocument();
});